Blog RSSExploits RSSFacebook

WEB

Date D   Description Plat. Author
2010-11-29   Wernhart Guestbook 2001.03.28 - Multiple SQL Injections 2 WEB Aliaksandr Hartsuyeu
2010-11-29   4homepages 4Images 1.7.x - 'categories.php' SQL Injection 1 WEB Ahmed Atif
2010-11-26   Easy Banner 2009.05.18 - 'index.php' Multiple Cross-Site Scripting Vulnerabilities 3 WEB Aliaksandr Hartsuyeu
2010-11-26   Easy Banner 2009.05.18 - '/member.php' Multiple SQL Injection / Authentication Bypass 3 WEB Aliaksandr Hartsuyeu
2010-11-24   SimpLISTic SQL 2.0 - 'email.cgi' Cross-Site Scripting 3 WEB Aliaksandr Hartsuyeu
2010-11-23   ZYXEL P-660R-T1 V2 - 'HomeCurrent_Date' Cross-Site Scripting 3 WEB Usman Saeed
2010-11-22   Hot Links SQL 3.2 - 'report.cgi' SQL Injection 3 WEB Aliaksandr Hartsuyeu
2010-11-18   CompactCMS 1.4.1 - Multiple Cross-Site Scripting Vulnerabilities (1) 3 WEB High-Tech Bridge SA
2010-11-16   Raised Eyebrow CMS - 'venue.php' SQL Injection 3 WEB Cru3l.b0y
2010-11-16   Simea CMS - 'index.php' SQL Injection 3 WEB Cru3l.b0y
2010-11-13   OpenWrt 10.03 - Multiple Cross-Site Scripting Vulnerabilities 2 WEB dave b
2014-10-17   Drupal 7.0 < 7.31 - 'Drupalgeddon' SQL Injection (PoC) (Reset Password) (2) 3 WEB Dustin Dörr
2014-10-17   Drupal 7.0 < 7.31 - 'Drupalgeddon' SQL Injection (Add Admin User) 3 WEB Claudio Viviani
2010-11-09   Ricoh Web Image Monitor 2.03 - Cross-Site Scripting 3 WEB thelightcosine
2010-11-10   WeBid 0.85P1 - Multiple Input Validation Vulnerabilities 3 WEB John Leitch
2010-11-10   PHPShop 2.1 EE - 'name_new' Cross-Site Scripting 2 WEB MustLive
2014-10-16   Drupal 7.0 < 7.31 - 'Drupalgeddon' SQL Injection (PoC) (Reset Password) (1) 2 WEB stopstene
2014-10-15   Indeed Job Search 2.5 iOS API - Multiple Vulnerabilities 3 WEB Vulnerability-Lab
2010-11-08   WordPress Plugin jRSS Widget 1.1.1 - 'url' Information Disclosure 3 WEB John Leitch
2010-11-08   WordPress Plugin Vodpod Video Gallery 3.1.5 - 'vodpod_gallery_thumbs.php' Cross-Site Scripting 3 WEB John Leitch
2010-11-08   WordPress Plugin SEO Tools 3.0 - 'file' Directory Traversal 3 WEB John Leitch
2010-11-08   WordPress Plugin WP Survey And Quiz Tool 1.2.1 - Cross-Site Scripting 3 WEB John Leitch
2010-11-08   WordPress Plugin FeedList 2.61.01 - 'handler_image.php' Cross-Site Scripting 3 WEB John Leitch
2010-11-05   Joomla! Component AutoArticles 3000 - SQL Injection 3 WEB jos_ali_joe
2010-11-05   Angel Learning Management System 7.3 - 'pdaview.asp' Cross-Site Scripting 3 WEB Wesley Kerfoot
2014-10-14   SEO Control Panel 3.6.0 - (Authenticated) SQL Injection 3 WEB Tiago Carvalho
2014-10-14   Tenda A32 Router - Cross-Site Request Forgery 3 WEB zixian
2014-10-14   YourMembers Plugin - Blind SQL Injection 3 WEB TranDinhTien
2014-10-14   Change CMS 3.6.8 - Multiple Cross-Site Request Forgery Vulnerabilities 3 WEB Krusty Hack
2014-10-14   Croogo 2.0.0 - Multiple Persistent Cross-Site Scripting Vulnerabilities 3 WEB LiquidWorm
2014-10-14   Croogo 2.0.0 - Arbitrary PHP Code Execution 3 WEB LiquidWorm
2014-10-14   PayPal Inc BB #85 MB iOS 4.6 - Authentication Bypass 3 WEB Vulnerability-Lab
2014-10-14   Bosch Security Systems DVR 630/650/670 Series - Multiple Vulnerabilities 3 WEB dun
2010-11-05   Joomla! 1.5.x - SQL Error Information Disclosure 3 WEB YGN Ethical Hacker Group
2010-11-02   Online Work Order Suite - Login SQL Injection 3 WEB VSN
2010-11-01   Douran Portal 3.9.7.55 - Arbitrary File Upload / Cross-Site Scripting 3 WEB ITSecTeam
2010-10-30   CMS WebManager-Pro 7.4.3 - Cross-Site Scripting / SQL Injection 3 WEB MustLive
2010-11-01   WordPress Plugin cformsII 11.5/13.1 - 'lib_ajax.php' Multiple Cross-Site Scripting Vulnerabilities 3 WEB Wagner Elias
2010-11-01   SmartOptimizer - Null Character Remote Information Disclosure 4 WEB Francois Harvey
2010-11-01   Elastix 2.0.2 - Multiple Cross-Site Scripting Vulnerabilities 3 WEB dave b
2009-05-25   Intergo Arcade Trade Script 1.0 - 'q' Cross-Site Scripting 3 WEB SmOk3
2009-05-29   212Cafe WebBoard 2.90 Beta - 'view.php' Directory Traversal 3 WEB MrDoug
2010-10-27   W-Agora 4.1.5 - Local File Inclusion / Cross-Site Scripting 3 WEB MustLive
2010-10-28   Feindura CMS Groupware - Multiple Local File Inclusion / Cross-Site Scripting Vulnerabilities 3 WEB Justanotherhacker.com
2009-06-03   i-Gallery 3.4/4.1 - 'streamfile.asp' Multiple Directory Traversal Vulnerabilities 3 WEB Stefano Angaran
2010-10-27   LES PACKS - 'ID' SQL Injection 3 WEB Cru3l.b0y
2010-10-27   Joomla! Component Projects 'com_projects' - SQL Injection / Local File Inclusion 3 WEB jos_ali_joe
2009-06-03   Flatnux 2009-03-27 - Multiple Cross-Site Scripting Vulnerabilities 3 WEB intern0t
2009-06-03   Sitecore CMS 6.0.0 rev. 090120 - 'default.aspx' Cross-Site Scripting 3 WEB intern0t
2014-10-09   Nessus Web UI 2.3.3 - Persistent Cross-Site Scripting 3 WEB Frank Lycops
2014-10-09   DrayTek VigorACS SI 1.3.0 - Multiple Vulnerabilities 3 WEB Digital Misfits
2014-10-09   BMC Track-It! - Multiple Vulnerabilities 2 WEB Pedro Ribeiro
2014-10-08   WordPress Plugin Creative Contact Form 0.9.7 - Arbitrary File Upload 3 WEB Gianni Angelozzi
2014-10-07   HttpCombiner ASP.NET - Remote File Disclosure 1 WEB Le Ngoc Son
2009-07-16   Skybluecanvas 1.1 r237 - 'admin.php' Directory Traversal 2 WEB MaXe
2014-10-06   Ultra Electronics 7.2.0.19/7.4.0.7 - Multiple Vulnerabilities 2 WEB OSI Security
2010-10-22   IBM Tivoli Access Manager for E-Business - '/ibm/wpm/webseal?method' Cross-Site Scripting 2 WEB IBM
2010-10-22   IBM Tivoli Access Manager for E-Business - '/ibm/wpm/user?method' Cross-Site Scripting 2 WEB IBM
2010-10-22   IBM Tivoli Access Manager for E-Business - '/ibm/wpm/rule?method' Cross-Site Scripting 2 WEB IBM
2010-10-22   IBM Tivoli Access Manager for E-Business - '/ibm/wpm/pop?method' Cross-Site Scripting 2 WEB IBM
2010-10-22   IBM Tivoli Access Manager for E-Business - '/ibm/wpm/os?method' Cross-Site Scripting 2 WEB IBM
2010-10-22   IBM Tivoli Access Manager for E-Business - '/ibm/wpm/gsogroup?method' Cross-Site Scripting 2 WEB IBM
2010-10-22   IBM Tivoli Access Manager for E-Business - '/ibm/wpm/gso?method' Cross-Site Scripting 2 WEB IBM
2010-10-22   IBM Tivoli Access Manager for E-Business - '/ibm/wpm/group?method' Cross-Site Scripting 1 WEB IBM
2010-10-22   IBM Tivoli Access Manager for E-Business - '/ibm/wpm/domain?method' Cross-Site Scripting 4 WEB IBM
2010-10-22   IBM Tivoli Access Manager for E-Business - '/ibm/wpm/acl?method' Cross-Site Scripting 3 WEB IBM
2010-10-22   IBM Tivoli Access Manager for E-Business - '/ivt/ivtserver?parm1' Cross-Site Scripting 3 WEB IBM
2010-10-22   W-Agora 4.2.1 - 'search.php?bn' Cross-Site Scripting 3 WEB MustLive
2010-10-22   W-Agora 4.2.1 - 'search.php3?bn' Traversal Local File Inclusion 3 WEB MustLive
2009-08-24   Radvision Scopia - '/entry/index.jsp' Cross-Site Scripting 3 WEB Francesco Bianchino
2009-08-20   PHP Scripts Now Riddles - '/riddles/list.php?catid' SQL Injection 3 WEB Moudi
2009-08-20   PHP Scripts Now Riddles - '/riddles/results.php?searchQuery' Cross-Site Scripting 3 WEB Moudi
2014-10-06   Bash CGI - 'Shellshock' Remote Command Injection (Metasploit) 2 WEB Fady Mohammed Osman
2009-07-20   PHP Scripts Now (Multiple Products) - 'bios.php?rank' SQL Injection 3 WEB 599eme Man
2009-07-20   PHP Scripts Now (Multiple Products) - 'bios.php?rank' Cross-Site Scripting 2 WEB 599eme Man
2010-10-21   pecio CMS 2.0.5 - 'target' Cross-Site Scripting 3 WEB Antu Sanadi
2010-10-21   Micro CMS 1.0 - 'name' HTML Injection (2) 3 WEB SecPod Research
2010-10-21   Wiccle Web Builder 2.0 - Multiple Cross-Site Scripting Vulnerabilities 3 WEB Veerendra G.G
2009-08-19   UloKI PHP Forum 2.1 - 'search.php' Cross-Site Scripting 3 WEB Moudi
2009-08-26   JCE-Tech PHP Video Script - 'index.php' Cross-Site Scripting 3 WEB Moudi
2009-08-26   Auction RSS Content Script - 'search.php?id' Cross-Site Scripting 2 WEB Moudi
2009-08-26   Auction RSS Content Script - 'rss.php?id' Cross-Site Scripting 2 WEB Moudi
2009-08-26   JCE-Tech SearchFeed Script - 'index.php' Cross-Site Scripting 3 WEB Moudi
2010-10-19   4Site CMS 2.6 - 'cat' SQL Injection 3 WEB High-Tech Bridge SA
2010-10-19   sNews 1.7 - 'snews.php' Cross-Site Scripting / HTML Injection 3 WEB High-Tech Bridge SA
2009-08-27   StandAloneArcade 1.1 - 'gamelist.php' Cross-Site Scripting 3 WEB Moudi
2009-08-26   DigiOz Guestbook 1.7.2 - 'search.php' Cross-Site Scripting 2 WEB Moudi
2009-08-27   E-Gold Game Series: Pirates of The Caribbean - Multiple SQL Injections 3 WEB Moudi
2009-08-28   QuarkMail - 'tf' Directory Traversal 3 WEB Securitylab.ir
2009-10-15   Skybluecanvas 1.1 r237 - 'admin.php' Multiple Cross-Site Scripting Vulnerabilities 3 WEB MaXe
2009-08-27   Wap-motor - 'image' Directory Traversal 2 WEB Inj3ct0r
2009-07-15   eCardMAX FormXP - 'survey_result.php' Cross-Site Scripting 3 WEB Moudi
2014-10-02   Moab < 7.2.9 - Authentication Bypass 2 WEB MWR InfoSecurity
2014-10-02   Epicor Enterprise 7.4 - Multiple Vulnerabilities 3 WEB Fara Rustein
2014-10-02   TestLink 1.9.11 - Multiple SQL Injections 3 WEB Portcullis
2014-10-02   PHPCompta/NOALYSS 6.7.1 5638 - Remote Command Execution 3 WEB Portcullis
2014-10-02   RBS Change Complet Open Source 3.6.8 - Cross-Site Request Forgery 3 WEB Krusty Hack
2014-10-02   WordPress Plugin All In One WP Security & Firewall 3.8.3 - Persistent Cross-Site Scripting 3 WEB Vulnerability-Lab
2014-10-02   Rejetto HTTP File Server (HFS) 2.3a/2.3b/2.3c - Remote Command Execution 3 WEB Daniele Linguaglossa
2014-10-02   Bacula-Web 5.2.10 - 'joblogs.php?jobid' SQL Injection 3 WEB wishnusakti
2010-10-15   eXV2 CMS - Multiple Cross-Site Scripting Vulnerabilities 3 WEB LiquidWorm
2010-01-19   AdvertisementManager 3.1 - 'req' Local/Remote File Inclusion 3 WEB indoushka
2009-08-07   PHP Easy Shopping Cart 3.1R - 'subitems.php' Cross-Site Scripting 3 WEB Moudi
2009-08-07   PHP Photo Vote 1.3F - 'page' Cross-Site Scripting 3 WEB Moudi
2010-10-14   TWiki 5.0 - bin/login Multiple Cross-Site Scripting Vulnerabilities 3 WEB DOUHINE Davy
2010-10-14   TWiki 5.0 - '/bin/view?rev' Cross-Site Scripting 3 WEB DOUHINE Davy
2010-10-13   PluXml 5.0.1 - Multiple Cross-Site Scripting / HTML Injection Vulnerabilities 3 WEB High-Tech Bridge SA
2010-10-13   Ronny CMS 1.1 r935 - Multiple HTML Injection Vulnerabilities 3 WEB High-Tech Bridge SA
2014-10-01   IPFire - CGI Web Interface (Authenticated) Bash Environment Variable Code Injection 3 WEB Claudio Viviani
2010-10-13   Joomla! Component Jstore - 'Controller' Local File Inclusion 3 WEB jos_ali_joe
2010-10-12   Oracle Fusion Middleware 10.1.2/10.1.3 - BPEL Console Cross-Site Scripting 2 WEB Alexander Polyakov
2010-10-11   Joomla! / Mambo Component com_trade - 'PID' Cross-Site Scripting 3 WEB FL0RiX
2010-10-06   Backbone Technology Expression 18.9.2010 - Cross-Site Scripting 3 WEB High-Tech Bridge SA
2009-06-15   Recipe Script 5.0 - 'First Name' HTML Injection 3 WEB ThE g0bL!N
2010-10-08   OPEN IT OverLook 5 - 'title.php' Cross-Site Scripting 3 WEB Anatolia Security
2009-06-22   Curverider Elgg 1.0 - Templates HTML Injection 3 WEB lorddemon
2010-10-08   Lantern CMS - '11-login.asp' Cross-Site Scripting 3 WEB High-Tech Bridge SA
2010-10-06   Joomla! Component Club Manager - 'cm_id' SQL Injection 3 WEB FL0RiX
2014-09-29   OpenFiler 2.99.1 - Cross-Site Request Forgery 3 WEB Dolev Farhi
2014-09-29   Microsoft Exchange - IIS HTTP Internal IP Address Disclosure (Metasploit) 3 WEB Nate Power
2014-09-29   GS Foto Uebertraeger 3.0 iOS - Local File Inclusion 3 WEB Vulnerability-Lab
2010-10-05   SquirrelMail Virtual Keyboard Plugin - 'vkeyboard.php' Cross-Site Scripting 3 WEB Moritz Naumann
2010-10-05   Elxis 2009.2 rev2631 - SQL Injection 3 WEB High-Tech Bridge SA
2010-10-04   Docebo 3.6 - 'description' Cross-Site Scripting 2 WEB High-Tech Bridge SA
2009-07-08   Linea21 1.2.1 - 'search' Cross-Site Scripting 3 WEB 599eme Man